← Vulnerability feed

Vulnerability record · CVE-2013-5316 · published 20 August 2013

CVE-2013-5316: Ritecms cross-site request forgery vulnerability

RRitecms · Ritecms

Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via an edit user action to cms/index.php.

6.8 CVSS 2.0 Medium EPSS 2.3% · top 17.6% CWE-352 · Cross-site request forgery
6.8CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via an edit user action to cms/index.php.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-5316 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-23934Ritecms os command injection vulnerabilityAn issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager…EPSS 16%7.5CVE-2025-67171Ritecms path traversal vulnerabilityIncorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.EPSS 0.82%7.5CVE-2025-67174Ritecms path traversal vulnerabilityA local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the ad…EPSS 1.3%7.2CVE-2025-67172Ritecms os command injection vulnerabilityRiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function.EPSS 0.92%7.2CVE-2021-46367Ritecms unrestricted file upload vulnerabilityRiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP fil…EPSS 30%6.8CVE-2025-67173Ritecms cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafte…EPSS 0.19%6.5CVE-2022-24247Ritecms path traversal vulnerabilityRiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerabilit…EPSS 4.2%6.5CVE-2022-24248Ritecms path traversal vulnerabilityRiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability…EPSS 21%

Source: NIST National Vulnerability Database (record CVE-2013-5316), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.